CVE-2025-25249: Heap-based buffer overflow in cw_acd daemon
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiSwitchManager cwacd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.The presence of security controls such as ASLR and PIE considerably raises the complexity and preparation effort required for exploitation.
Other sources
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.18 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25249?
CVE-2025-25249 has a critical severity rating due to the potential for remote unauthenticated attack leading to arbitrary code execution.
How do I fix CVE-2025-25249?
To mitigate CVE-2025-25249, upgrade FortiOS to version 7.6.4 or later, FortiSwitchManager to version 7.2.7 or later, or follow vendor guidance for affected products.
Which products are affected by CVE-2025-25249?
CVE-2025-25249 affects multiple versions of FortiOS, FortiSwitchManager, and FortiSASE.
Can CVE-2025-25249 allow an attacker to execute code remotely?
Yes, CVE-2025-25249 allows a remote unauthenticated attacker to execute arbitrary code through crafted requests.
What is the nature of the vulnerability in CVE-2025-25249?
CVE-2025-25249 is a heap-based buffer overflow vulnerability that can be exploited by attackers.